Users Guide

Table Of Contents
While deleting ACL rules, the following conditions apply:
Enter the exact no form of the CLI command. Each ACL rule is an independent entity. For example, the rule, deny ip any any is
dierent from deny ip any any count.
For example, if you congured the following rules:
deny ip 1.1.1.1/24 2.2.2.2/24
deny ip any any
Using the no deny ip any any command deletes only the deny ip any any rule.
To delete the deny ip 1.1.1.1/24 2.2.2.2/24 rule, you must explicitly use the no deny ip 1.1.1.1/24 2.2.2.2/24
command.
NOTE: Wildcard option is not supported.
You can no longer congure the same ACL rule multiple times using dierent sequence numbers. This option prevents duplicate rules
from being entered in the system and taking up memory space.
When you upgrade from a previous release to release 10.4.2 or later, the upgrade procedure removes all duplicate ACL rules and only
one instance of an ACL rule remains in the system.
L2 and L3 ACLs
Congure both L2 and L3 ACLs on an interface in L2 mode. Rules apply if you use both L2 and L3 ACLs on an interface.
L3 ACL lters packets and then the L2 ACL lters packets
Egress L3 ACL lters packets
Rules apply in order:
Ingress L3 ACL
Ingress L2 ACL
Egress L3 ACL
Egress L2 ACL
NOTE
: In ingress ACLs, L2 has a higher priority than L3 and in egress ACLs, L3 has a higher priority than L2.
Table 65. L2 and L3 targeted trac
L2 ACL / L3 ACL Targeted trac
Deny / Deny L3 ACL denies
Deny / Permit L3 ACL permits
Permit / Deny L3 ACL denies
Permit / Permit L3 ACL permits
Assign and apply ACL lters
To lter an Ethernet interface, a port-channel interface, or a VLAN, assign an IP ACL lter to the corresponding interface. The IP ACL
applies to all trac entering a physical, port-channel, or VLAN interface. The trac either forwards or drops depending on the criteria and
actions you congure in the ACL lter.
To change the ACL lter functionality, apply the same ACL lters to dierent interfaces. For example, take ACL “ABCD” and apply it using
the in keyword and it becomes an ingress ACL. If you apply the same ACL lter using the out keyword, it becomes an egress ACL.
You can apply an IP ACL lter to a physical, port-channel, or VLAN interface. The number of ACL lters allowed is hardware-dependent.
1040
Access Control Lists